diff --git a/docs/evidence/statehub-inbox-pilot-20260905.json b/docs/evidence/statehub-inbox-pilot-20260905.json deleted file mode 100644 index 185b3e8..0000000 --- a/docs/evidence/statehub-inbox-pilot-20260905.json +++ /dev/null @@ -1,116 +0,0 @@ -{ - "date": "2026-09-05", - "scope": "frozen-source-snapshot; no production reader switch", - "source": "state-hub/primary/railiance01", - "captured_at": "2026-09-05T08:38:37.982640+00:00", - "owner_commit": "6fb5ce2", - "package_enable_commit": "6972db5", - "image_digest": "sha256:a3461c0da805ef2b58caa0c862be3dc6562abcca186300d1257df9b96569b4c0", - "endpoint": "GET /ports/projections/statehub-inbox", - "import": { - "runs": [ - { - "status": "validated", - "count": 20, - "content_hash": "f952b1fb46469f43bbf8ec7de1041a6feae943708c3496d8b55287428e6ed60d" - }, - { - "status": "applied", - "count": 20, - "content_hash": "f952b1fb46469f43bbf8ec7de1041a6feae943708c3496d8b55287428e6ed60d" - }, - { - "status": "noop", - "count": 20, - "content_hash": "f952b1fb46469f43bbf8ec7de1041a6feae943708c3496d8b55287428e6ed60d" - } - ], - "target_hash": "f952b1fb46469f43bbf8ec7de1041a6feae943708c3496d8b55287428e6ed60d", - "source_count": 20 - }, - "parity": { - "source_count": 20, - "snapshot_hash": "f952b1fb46469f43bbf8ec7de1041a6feae943708c3496d8b55287428e6ed60d", - "cases": [ - { - "params": {}, - "count": 19, - "content_hash": "1b3d5beff1d081bec7c552d0c463ffe48999bd75caf5bae1189e421651467295", - "mode": "snapshot-pilot", - "parity": true - }, - { - "params": { - "unread_only": "true" - }, - "count": 0, - "content_hash": "4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945", - "mode": "snapshot-pilot", - "parity": true - }, - { - "params": { - "from_agent": "activity-core" - }, - "count": 8, - "content_hash": "a6fb59f2a35ecc7c9c445bbcd1056955828062179ee52b2c15f497ea76a5656a", - "mode": "snapshot-pilot", - "parity": true - }, - { - "params": { - "from_agent": "missing-pilot-sender" - }, - "count": 0, - "content_hash": "4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945", - "mode": "snapshot-pilot", - "parity": true - }, - { - "params": { - "limit": "1" - }, - "count": 1, - "content_hash": "84a3d3ea5eb407629009eef7440fca14219be63486ab7d61b7e1f2d44adc3bba", - "mode": "snapshot-pilot", - "parity": true - }, - { - "params": { - "limit": "1000" - }, - "count": 19, - "content_hash": "1b3d5beff1d081bec7c552d0c463ffe48999bd75caf5bae1189e421651467295", - "mode": "snapshot-pilot", - "parity": true - } - ], - "no_auth": 401, - "bad_auth": 401, - "post": 405, - "scope": "frozen-source-snapshot" - }, - "live_source_check": { - "live_source_api_count": 19, - "live_source_api_hash": "1b3d5beff1d081bec7c552d0c463ffe48999bd75caf5bae1189e421651467295", - "frozen_inbox_hash": "1b3d5beff1d081bec7c552d0c463ffe48999bd75caf5bae1189e421651467295", - "matches_frozen": true - }, - "transport_from_state_hub_without_token": 401, - "rollback": { - "configuration_revision": 25, - "rollback_revision": 27, - "readyz": 200, - "disabled_inbox": 404, - "restored_revision": 28, - "parity_repeated": true - }, - "checks": { - "hub_core_tests_passed": 116, - "packaging_tests_passed": 11, - "helm_lint": "passed", - "server_dry_run": "passed", - "family_validation": "14 declarations, 0 errors, 1 existing reef-railiance warning", - "verify_live": "passed" - } -} diff --git a/docs/evidence/statehub-inbox-pilot-20260905.md b/docs/evidence/statehub-inbox-pilot-20260905.md deleted file mode 100644 index 6c22dc4..0000000 --- a/docs/evidence/statehub-inbox-pilot-20260905.md +++ /dev/null @@ -1,38 +0,0 @@ -# Private State Hub inbox snapshot pilot — 2026-09-05 - -T08 receiving-readiness proof is complete. Hub Core exposes the authenticated, -GET-only `/ports/projections/statehub-inbox` for the literal `state-hub` inbox. -It is private, default-disabled in the chart, and enabled in the current private -production package. State Hub remains the writer; no production reader switched. - -A consistent source transaction captured 20 historical rows (including archived -rows and thread closure) at 08:38:37.982640 UTC. Import preserved identities, -timestamps and flags; validation, apply, identical replay/no-op and target hash -all agree. The visible inbox contains 19 rows. Six read cases match ordered IDs -and normalized whole-record hashes, covering unread/sender filters and limits. -The live source inbox also matched the frozen oracle at verification time. -Bodies and credentials are excluded from this evidence. - -Missing/bad authentication returns 401; POST returns 405. Scoped NetworkPolicy -admission now permits State Hub API pods to reach the authenticated boundary. -The prior prefix-only probe overlooked existing `/ports/messaging/messages`, -`/ports/events/progress` and named projection ports. Those native envelopes do -not by themselves establish State Hub history/read/archive compatibility. - -Image source is `hub-core@6fb5ce2`; package enablement is -`rapp-core-hub@6972db5`. Exact digest and content hashes are in the adjacent JSON. -Helm revision 25 installed the image with the pilot disabled; revision 26 enabled -it after import. Rollback to configuration 25 produced revision 27, readiness -200 and pilot 404. Roll-forward to revision 28 passed the same parity cases and -`make verify-live`. No State Hub image or writer configuration changed. - -Validation: 116 owner tests, 11 packaging tests, Helm lint and server dry-run -passed. Family validation passed 14 declarations with zero errors and one -pre-existing reef-railiance warning. The rmgr wrapper lacked jsonschema; the -same family validator succeeded with the State Hub virtualenv interpreter. - -Residual **HUB-WP-0011**, tracked by **STATE-WP-0079-T09**, owns ongoing monotonic -freshness/staleness, caller-specific credentials, canonical/alias scope and a -reviewed production reader switch. The operator-authenticated frozen pilot must -not be presented as a fresh inbox. B2/B3 migration and message-writer cutover -remain open; this proof does not retire those families. diff --git a/workplans/HUB-WP-0010-statehub-inbox-read-pilot.md b/workplans/HUB-WP-0010-statehub-inbox-read-pilot.md index b4b28ee..6b19424 100644 --- a/workplans/HUB-WP-0010-statehub-inbox-read-pilot.md +++ b/workplans/HUB-WP-0010-statehub-inbox-read-pilot.md @@ -4,17 +4,13 @@ type: workplan title: "State Hub inbox read projection pilot" domain: infotech repo: hub-core -status: finished +status: active owner: codex topic_slug: infotech created: "2026-09-05" updated: "2026-09-05" related: - STATE-WP-0079 -quality_dod: DoD-Ok -quality_dod_at: "2026-09-05" -quality_dod_by: codex -quality_dod_note: "Frozen snapshot parity, auth, rollback and live verification passed; residual HUB-WP-0011 owns production cutover." quality_dor: DoR-Ok quality_dor_at: "2026-09-05" quality_dor_by: codex @@ -22,16 +18,14 @@ quality_dor_note: >- STATE-WP-0079-T08 requests one read-only inbox parity proof. The runtime has an empty agent_messages table and an operator token; named-port messages are a distinct envelope contract. Scope excludes production message writers. -state_hub_workstream_id: "8c06208c-c84a-5001-8a57-47fb206c67ec" --- ## Deliver the opt-in receiver contract ```task id: HUB-WP-0010-T01 -status: done +status: progress priority: high -state_hub_task_id: "b61aaed1-710d-5d81-a2af-1193f5dafe09" ``` Add an authenticated, GET-only `/ports/projections/statehub-inbox` pilot for one @@ -43,9 +37,8 @@ State Hub remains the writer. Existing `/ports/messaging/messages` is unchanged. ```task id: HUB-WP-0010-T02 -status: done +status: todo priority: high -state_hub_task_id: "9266d98c-9f88-5184-920d-a5c498b40664" ``` Validate source/count/hash/thread closure before importing to an empty receiver. @@ -54,9 +47,3 @@ rows refuse overwrite. Verify parity over a fixed source snapshot with read-only queries, auth failures and rollback by disabling the pilot. Packaging/deployment belongs to rapp-core-hub. Do not claim continuous freshness or switch clients from the sole production message writer based on a one-time snapshot. - -## Completion evidence and residual handoff - -See `docs/evidence/statehub-inbox-pilot-20260905.md` and its JSON receipt. -HUB-WP-0011 was created before closure and owns freshness, caller identity and -production reader cutover; STATE-WP-0079-T09 tracks that gate. diff --git a/workplans/HUB-WP-0011-statehub-inbox-freshness-and-cutover.md b/workplans/HUB-WP-0011-statehub-inbox-freshness-and-cutover.md deleted file mode 100644 index 0959ef1..0000000 --- a/workplans/HUB-WP-0011-statehub-inbox-freshness-and-cutover.md +++ /dev/null @@ -1,66 +0,0 @@ ---- -id: HUB-WP-0011 -type: workplan -title: "State Hub inbox freshness and reader cutover" -domain: infotech -repo: hub-core -status: proposed -owner: codex -topic_slug: infotech -created: "2026-09-05" -updated: "2026-09-05" -origin: residual -origin_ref: HUB-WP-0010 -related: - - STATE-WP-0079 - - RAPPCOREHUB-WP-0004 -state_hub_workstream_id: "3c8034fc-fd90-58f5-99bc-99b4f93e5ee1" ---- - -## Establish ongoing inbox freshness - -```task -id: HUB-WP-0011-T01 -status: todo -priority: high -state_hub_task_id: "588e4b58-4694-513c-8e7a-1fab38fb6ce3" -``` - -The deployed inbox reader is an explicitly labeled one-time snapshot pilot. -Define and implement monotonic source revision/cursor semantics, atomic refresh, -read/archive updates, deletes/retention treatment and stale-source signaling. -The initial importer deliberately refuses different existing rows; do not turn -it into an unconditional overwrite loop. Prove recovery and idempotency without -creating a second message writer. Decide the source/destination ownership -boundary before live client traffic moves. - -## Admit the actual reader identity and full scope semantics - -```task -id: HUB-WP-0011-T02 -status: wait -priority: high -state_hub_task_id: "35c5ae8b-f357-512f-af40-bc5915f3c02d" -``` - -Replace pilot operator authentication with the reviewed caller-specific access -contract and delivered workload credential. Preserve recipient authorization, -broadcast behavior, repository canonical/alias resolution, source timestamps -and thread/read/archive semantics for the selected reader. The existing pilot -supports only one literal agent and exact sender filters. Never distribute the -operator token as an application credential. - -## Execute one reviewed client switch - -```task -id: HUB-WP-0011-T03 -status: wait -priority: high -state_hub_task_id: "61c727a5-f4b1-54c0-b634-7d71a5416496" -``` - -After T01/T02 pass, produce live freshness and parity receipts for one State Hub -inbox reader; verify rollback to the current State Hub endpoint. Then execute -that bounded reader switch with the concrete deployment authorization. Retire -its compatibility dependency only after metered acceptance. Message-writer -cutover and all other route families remain separate STATE-WP-0079 work.